What safeguarding auditors actually look for in e-money firms
Segregation on a org chart is not enough. Examiners and independent reviewers follow the money through accounts, reconciliations, and escalation paths.
When we open a safeguarding controls audit, the first question is rarely about policy wording. It is whether relevant funds can be identified, held apart from firm money, and rebuilt from bank evidence on any given day.
We start with account structure: named safeguarding accounts, correct titling, and payment rails that cannot silently blend client balances into operating cash. Then we sample reconciliations—not only the final signed sheet, but the source extracts, timing cuts, and how breaks are aged.
Firms in Hong Kong often underestimate float and settlement lag. A control that looks tidy at month-end can fail on a busy Tuesday when wallet top-ups and merchant settlements collide. Good evidence shows who noticed the variance, who approved the hold, and when the shortfall procedure would have triggered.
If your board pack only shows “reconciled daily” without samples or exception metrics, expect a finding. Strengthen the narrative with concrete population sizes, break ageing, and dual-control proof on movements out of safeguarding accounts.